Wekan logo

Wekan

Open source kanban board application built with Meteor

Alternative to: trello


About Versions (307)

v11.17

2026-08-28

Binaries in these bundles

Each bundle carries a Node.js, a FerretDB and the MongoDB Database Tools. Which source has a given CPU varies from release to release - nodejs.org builds some architectures, unofficial-builds others, and the wekan/node-patches build the ones neither of them does - and not every source publishes a checksum. This is what went into this release, and which downloads were checked against a published SHA256.

BundleBinaryFromVersionCheckedSHA256
amd64FerretDBwekan/FerretDBv1.62.0verified42b6031e48a6a44c…
amd64Node.jsnodejs.orgv24.20.0verified2f2c0da162318f0d…
arm64FerretDBwekan/FerretDBv1.62.0verified930b33cbc83b35cb…
arm64Node.jsnodejs.orgv24.20.0verified5f4ddab610c1ab20…
armhfFerretDBwekan/FerretDBv1.62.0verified2963fdfc690f0cca…
armhfNode.jswekan/node-patchesv24.20.0verifiedb8ed7065d44f0afe…
armv6FerretDBwekan/FerretDBv1.62.0verified58f2f6ddff05b951…
armv6Node.jswekan/node-patchesv24.20.0verifiedd5cefa6f8cc4acb1…
armv7FerretDBwekan/FerretDBv1.62.0verified2963fdfc690f0cca…
armv7Node.jswekan/node-patchesv24.20.0verifiedc04c81e539347f39…
i386FerretDBwekan/FerretDBv1.62.0verified96919f54f4dabb29…
i386Node.jswekan/node-patchesv24.20.0verifiedbb44927307460dcf…
mac-arm64FerretDBwekan/FerretDBv1.62.0verifiedaf5707904580f34f…
mac-arm64Node.jsnodejs.orgv24.20.0verifiedb7bf7707070b950b…
mac-x64FerretDBwekan/FerretDBv1.62.0verified57dc580ad9b7a8bf…
mac-x64Node.jsnodejs.orgv24.20.0verified26fc30891004603d…
ppc64leFerretDBwekan/FerretDBv1.62.0verifiedc93d394f1ce56534…
ppc64leNode.jsnodejs.orgv24.20.0verified341307dcee20d883…
riscv64FerretDBwekan/FerretDBv1.62.0verified404bee52f8bb86fa…
riscv64Node.jsunofficial-builds.nodejs.orgv24.20.0verifieda149c5bf85f98ff1…
s390xFerretDBwekan/FerretDBv1.62.0verified7edbadece06a4921…
s390xNode.jsnodejs.orgv24.20.0verifiedca381121cb5a8d38…
win-arm64FerretDBwekan/FerretDBv1.62.0verified9318c87775c42b41…
win-arm64Node.jsnodejs.orgv24.20.0verified31c6799744de8a54…
win64FerretDBwekan/FerretDBv1.62.0verified25fec66a71c9fe50…
win64Node.jsnodejs.orgv24.20.0verified6cac9ffbca8f6a47…

A row saying no checksum published is not a failed check - it is a source that publishes nothing to check against. Those are the ones worth fixing at the source.

v11.17 2026-08-28 WeKan ® release

In short: HostnameBleed, found by GitHub CodeQL, makes tenant-hostname translation coverage compare example domains as exact text. Card titles keep markdown links clickable and mouse text selection native, while comment markdown retains its per-render fallback. REST user deletion now reports the database-confirmed outcome and documents both success and missing-user responses. Translations complete Swati, begin Sesotho and raise the measured essentially-complete total to 197 while protecting target-language vocabulary and code tokens. The table below is carried over from the release under this one, and is refilled from each build’s provenance.tsv when this release is made.

PlatformBinaryFromVersionSHA256
amd64Node.jsnodejs.orgv24.19.014b342e71204f811bde6153be8e04b62aef63c236fef92b55f9c83154b409647
amd64FerretDBwekan/FerretDBv1.53.0eae1f0a8f73bfc979738bfff7284d40fd1bc55de2cc56514721fc155c3624f7d
arm64Node.jsnodejs.orgv24.19.001443c1e1a29e531ccad5a46fefa6df490d2189c49f7955904aecdbb0fe86fdc
arm64FerretDBwekan/FerretDBv1.53.0bdc50caee3ac28495b42d2130b94a042a9dd6d3a38f732cac02b648f36c891da
mac-arm64Node.jsnodejs.orgv24.19.03f1cf157479c1480352083105e13faf9d008ede98e7e157746b6df940d197b94
mac-arm64FerretDBwekan/FerretDBv1.53.0cb14ffe93e285903e5a8a9c1821687ddb5b8a979a11c584bf4af534b272c6d3e
mac-x64Node.jsnodejs.orgv24.19.0d35e95230f46f6f0751df497c56622c6735e05d5e1fb1630996a005b9d328fe4
mac-x64FerretDBwekan/FerretDBv1.53.0d97dfa9afa60aa05f25384327de82efe7b71d958ed24c1f66618284294a65cd3

This release fixes the following SECURITY ISSUES found by GitHub CodeQL code scanning:

HostnameBleed: tenant hostname examples are compared as exact text. Thanks to GitHub CodeQL code scanning and xet7.

HostnameBleed covers code scanning alerts #435 and #436, rule js/incomplete-hostname-regexp (CWE-20), in tests/marathiTranslationProgress.test.cjs. The test passed a.example.com and kanban.example.org directly to RegExp, so each dot acted as a wildcard. A wrong hostname such as aXexampleXcom could therefore satisfy coverage that was meant to require the exact documentation example.

The affected code runs only in a translation regression test over hardcoded strings. It is not shipped in the server or browser bundle, accepts no request or user input and denies no operation, so there is no attributable runtime attempt to record in Admin Panel → Problems.

The test now uses exact includes() comparisons. Positive and negative cases prove literal dots are required, while a repository-wide source guard detects the reported loop-to-RegExp shape and confirms it exists nowhere else in tracked first-party JavaScript.

and fixes the following bugs:

Card titles - links, editing and mouse selection remain distinct gestures.

Markdown links in minicard titles remain clickable. Thanks to jullbo and xet7.

The fixed-width transparent edit overlay previously covered the leading half of every title, which swallowed every pixel of a short rendered markdown link. The title container itself is now the edit target, while nested viewer links receive and stop their own click before editing can open.

Keyboard access remains on the title container, and its focus semantics are preserved. Positive and negative source tests cover the event boundary; a live Chromium regression edits a title to a markdown link, clicks it, and proves that the editor stays closed.

Mouse dragging in card title editors selects text. Thanks to rmb82 and xet7.

Card sorting and opened-card window dragging previously claimed mouse gestures that began inside a title textarea. Those editors and their controls are now excluded from sorting, and the window-drag handler returns before suppressing the browser’s native selection behavior.

Source regressions pin both drag boundaries. A live Chromium test drags across an opened-card title, verifies a non-empty selection range and confirms the card window did not move.

Card interaction regressions use stable browser targets. Thanks to jullbo, rmb82 and xet7.

Specs that open a card now activate the shared wrapper-link helper instead of clicking title text, whose intended action is inline editing. The Firefox mouse selection regression keeps both drag coordinates over rendered title text, and the failed-copy negative check uses the stable board canvas rather than a strict union that fails when both healthy regions are visible.

The affected title-selection, failed-copy, LTR/RTL card-panel and board-comment paths pass together in a fresh Chromium run. Firefox and WebKit remain covered by the full Docker browser matrix.

Comments and Activities - one markdown render cannot blank surrounding UI.

Comment markdown retains its independent rendering fallback. Thanks to rmb82 and xet7.

The per-render exception boundary already added in 75a23b76a catches markdown or sanitization failures and returns safe escaped text, so one bad comment does not abort the card comment list or Activities rendering. The reported French emphasis, list and literal greater-than forms now run through the real shipped markdown configuration as explicit regression coverage.

REST API - user deletion responses reflect the authoritative database result.

User deletion confirms removal and reports missing users. Thanks to AhmedLukman and xet7.

The route previously discarded removeAsync’s result and returned the requested id even when no account matched. It now returns 200 only when exactly one user was removed, returns a deterministic 404 for zero matches and treats unexpected counts or database failures as internal errors.

Repeatable response annotations let the OpenAPI generator document the exact 200 and 404 response bodies. Unit and negative tests cover authorization and every removal outcome, regenerated YAML matches the route source byte for byte, and a live Chromium API test confirms deletion in MongoDB before repeating the request and receiving 404.

and improves the following translations:

Translations - Swati reaches completion, Sesotho begins and measured completion assertions stay current.

Swati is complete. Thanks to xet7.

The remaining 417 Swati strings now cover jobs, storage, migrations, backups, privacy, monitoring, repositories and imports. A same-script vocabulary audit also replaces the Zulu word ibhodi with the Swati libhodi.

Regression coverage proves the locale has no English placeholders, preserves the exact source placeholder and HTML inventories and uses Swati vocabulary. These direct translations have lower confidence than reviewed human work and remain open to correction by Swati speakers.

Sesotho translation begins with core board activity. Thanks to xet7.

The first 50 Sesotho strings translate activity titles and descriptions, members, comments, dates, attachments, labels, checklists, custom fields, archives and imports. Source placeholders remain exact, and a language-specific regression checks Sesotho vocabulary while recording the 2,117 strings still untranslated at this commit.

Translation completion assertions match the measured files. Thanks to xet7.

The translation documentation now reports 197 essentially complete locales, and the Northern Sotho regression expects its measured zero remaining English placeholders. Tests calculate these values from the locale files so stale completion claims fail visibly.

Thanks to above GitHub users for their contributions and translators for their translations.